Risk taxonomy
Every score decomposes into
named, weighted signals.
A risk score you cannot decompose is an opinion. This page publishes the full WalletDNA taxonomy: every signal category, the actual weight it carries, and how it is detected. The same breakdown appears on every report, factor by factor.
How the score is built
Scoring is deterministic and versioned (current methodology: v2.1). Every wallet starts at a baseline of 5. Signals add or subtract their published weight, and the result is clamped to 0–100. One rule overrides the arithmetic: a direct sanctions match floors the score in the CRITICAL band, because no amount of good behavior offsets a designation. Reports state the methodology version they were scored under, so a score produced today can be tied to the exact rules that produced it.
| Band | Score range | Reading |
|---|---|---|
| LOW | 0–20 | No material risk signals detected. |
| MODERATE | 21–40 | Weak signals present; nothing that alone warrants escalation. |
| ELEVATED | 41–60 | Signals worth a documented review before proceeding. |
| HIGH | 61–80 | Serious signals; enhanced due diligence is warranted. |
| CRITICAL | 81–100 | Sanctions designation or equivalent; do not proceed without legal review. |
The nine signal categories
Sanctions
Critical driverDirect listing on a sanctions register, or measurable fund flow to and from listed addresses. A direct match floors the score in the CRITICAL band regardless of every other signal: no amount of good behavior offsets a designation.
| Signal | Score weight | Detection |
|---|---|---|
| Sanctions list match | score floors at 82 (CRITICAL) | Address screened against OFAC SDN and international sanctions data, refreshed daily. The matching authority is named on the report. |
| Volume via sanctioned addresses | +12 to +45 by share of volume | Counterparty graph analysis. Tiers at any exposure, 1%, 10%, and 30% of traced volume. |
Threat actors
Critical driverAttribution to a known criminal operation: hacker groups, drainers, ransomware operators, darknet markets. Attribution comes from a curated entity database with sources cited on the report.
| Signal | Score weight | Detection |
|---|---|---|
| Known threat actor | +65 | Entity attribution database with source citations, assembled from sanctions designations, incident reports, and security research. |
Mixers and obfuscation
Major driverUse of services whose purpose is breaking the chain of custody. Being a mixer scores highest; direct interaction with one is scored separately and shown with the evidencing transactions.
| Signal | Score weight | Detection |
|---|---|---|
| Cryptocurrency mixer | +60 | The wallet itself is an attributed mixing service. |
| Tornado Cash interaction | +25 | Direct on-chain transactions with Tornado Cash contracts. |
| Railgun interaction | +20 | Direct on-chain transactions with the Railgun privacy protocol. |
| CoinJoin pattern | +15 | Structural detection of CoinJoin-style transactions in Bitcoin history. |
High-risk counterparty exposure
Moderate driverFund flow through counterparties that are themselves high-risk (mixers, threat actors, previously flagged wallets), measured as a share of traced volume so one small transfer does not dominate the score.
| Signal | Score weight | Detection |
|---|---|---|
| Volume via high-risk counterparties | +8 to +25 by share of volume | Counterparty graph analysis. Tiers at any exposure, 10%, and 30% of traced volume. |
Contract risk
Moderate driverSmart contracts whose code or operator cannot be verified. Unverified code is a classic rug-pull and drainer pattern; an unattributed contract is a milder version of the same uncertainty.
| Signal | Score weight | Detection |
|---|---|---|
| Unverified contract code | +22 | Contract source not verified on the chain's canonical explorer. |
| Unattributed smart contract | +12 | Contract with no entity attribution in the label database. |
Cross-chain movement
Context signalBridges are legitimate infrastructure that also serves as an investigative blind spot. WalletDNA scores bridge involvement lightly and instead traces through it: canonical-bridge deposits are decoded from calldata to recover the destination recipient.
| Signal | Score weight | Detection |
|---|---|---|
| Cross-chain bridge | +10 | Attributed bridge contracts on 18 chains; deposit transactions decoded to name the destination-chain recipient where the bridge encodes it. |
Behavioral signals
Context signalWeak signals that shade a score rather than drive it: young wallets have thin history, whale balances raise stakes, burst activity patterns lower attribution confidence.
| Signal | Score weight | Detection |
|---|---|---|
| New wallet (under 1 year) | +8 | First transaction timestamp. |
| Whale-sized balance | +3 | Balance threshold per chain. |
| Low attribution confidence | +3 to +6 | Composite of history depth, burst-activity detection, and entity coverage. |
Mitigating signals
Reduces riskSignals that reduce the score. Attribution to a regulated venue, proof-of-reserves disclosure, long history, and majority flow through verified exchanges all argue the wallet is what it appears to be.
| Signal | Score weight | Detection |
|---|---|---|
| Verified identity | -12 | Entity attribution at the highest confidence tier. |
| Proof of Reserves disclosed | -8 | Wallet appears in a published exchange PoR attestation. |
| Majority volume via verified exchanges | -5 | At least half of traced volume flows through attributed exchanges. |
| Known exchange wallet | -3 to -4 | Entity attribution to an exchange, or a PoR-verified reserve address. |
| Long-established wallet (3+ years) | -3 | First transaction timestamp. |
| DeFi protocol activity | -3 | Interaction pattern with attributed DeFi protocols. |
Spam and impersonation filtering
Context signalNot a score input but a data-integrity layer: scam airdrops and address-poisoning tokens are detected and excluded so they can neither inflate a report nor trigger alerts. Each flagged token states which rule caught it.
| Signal | Score weight | Detection |
|---|---|---|
| Token impersonation | excluded from value calculations | Symbols claiming major tokens (USDT, USDC, WETH) are checked against a verified contract registry; a mismatch is decisive. |
| Phishing-pattern symbols | excluded from value calculations | URL fragments, claim/reward keywords, and malformed tickers, supplemented by a third-party token security database that never overrides on-chain verdicts. |
Alert severities
Monitoring grades every alert into one of four tiers, so a fresh sanctions designation never reads like a routine score wobble. Email subjects, Telegram messages, and dashboard badges all use the same tiers.
CRITICAL
A fresh sanctions designation, or the score enters the CRITICAL band (81+).
HIGH
The score crosses into the HIGH band (61+), even when the numeric move is small.
ELEVATED
A material risk-score change below the HIGH band.
INFO
New transaction activity and routine monitoring events.
What the score will not do
- Manufacture a verdict from missing data. If a data source fails mid-analysis, the report says so and the affected sections are marked degraded. A failed sanctions screen is reported as unscreened, never as clean.
- Hide behind the number. Every report carries the per-factor breakdown: each signal, its weight, and the evidence rows behind it, down to the transactions that triggered it.
- Drift silently. Weight changes bump the methodology version, and each report records the version that scored it.
See the taxonomy applied to a real wallet
Run a free analysis and open the score breakdown. Ten analyses per month, no card required.
Analyze a wallet freeFull methodology write-up at walletdna.com/methodology